R07 is the ACH return code for "Authorization Revoked by Customer." The consumer had authorized your debits, then revoked that authorization, and told their bank. The bank returns the debit as R07 after the customer signs a written statement of unauthorized debit. It's an extended return, so it can arrive up to 60 calendar days after settlement. Nacha counts R07 as unauthorized, against a 0.5% threshold. You can't send that debit again. On a payment plan, stop the debits and talk to the customer before anything else.
What does R07 mean?
R07 is "Authorization Revoked by Customer." Nacha describes it as the customer revoking the authorization they previously gave the business for this debit. The customer agreed once. They have since withdrawn it, and they've told their bank.
R07 is for consumers. Nacha's code table limits it to consumer debit types, and the corporate types (CCD and CTX) aren't on its list.
Who sends an R07, and how long do they have?
The customer's bank (the RDFI), after the customer tells it the authorization was revoked. Nacha groups "authorization revoked" with unauthorized debits in the section of its rules on the written statement of unauthorized debit. So the bank needs the customer's signed statement first.
Consumer debits carry an extended right of return of 60 days. Under Nacha's rules, an extended return must reach the business's bank by the opening of business on the banking day after the 60th calendar day following the debit's settlement date. So an R07 can arrive weeks after a payment looked complete.
Does R07 count against my return rates?
Yes, in the strictest group. Nacha's unauthorized return rate covers R05, R07, R10, R11, R29 and R51. Its threshold is 0.5% of debits over the preceding 60 days or two calendar months. Nacha lowered it from 1.0%. R07 also counts toward the 15.0% overall level for all debit returns.
Can I send the debit again?
No. Nacha's position is that an unauthorized debit cannot be remedied. Reinitiating any debit returned as unauthorized is an improper reinitiation. A later debit is allowed only if you get a new authorization after you receive the return. Nacha says you can't get that approval in advance.
Stripe reports R07 as debit_not_authorized, meaning the payment doesn't have an authorized mandate. Its guidance is to collect a new mandate first. After a customer's first unauthorized dispute, Stripe revokes the mandate. A second one blocks the bank account.
What should I do when a plan payment comes back R07?
- Stop every scheduled debit to that account. The rest of the plan rests on the authorization the customer revoked.
- Contact the customer. Find out whether they want to stop the plan, change it or pay another way.
- If they want to continue, get a new authorization after the return, in writing, with the amounts and dates.
- Settle the missed payment directly. Stripe notes that ACH disputes inside the time limits are final and can't be challenged through the ACH network.
Example: a customer revokes authorization after payment six of twelve. The $1,108.33 debit for payment six comes back R07 five weeks later. Payments seven to twelve can't be debited until the customer signs a new authorization.
For how this plays out across a plan, see ACH returns on payment plans.
General information, not legal advice.
- Nacha: ISO 20022 guide to mapping U.S. ACH return codes (return code names, descriptions and SEC codes)
- Nacha: differentiating unauthorized return reasons
- Nacha: RMAG Originator Essentials
- Nacha: ACH Risk Management 2023 rule text, Appendix Four (extended return timing)
- Nacha: ACH network risk and enforcement topics
- Stripe: ACH Direct Debit
- Stripe: network decline codes
- Stripe: blocked bank accounts
Every figure on this page was checked against these sources on Oct 6, 2026. General information, not legal or tax advice.